AWS Privilege Escalation — DevOps & Infrastructure agent for Claude Code
Map the paths from each AWS IAM principal to administrative control, naming the calls that walk each one.
How to install AWS Privilege Escalation
Installs to ~/.claude/agents/mvanhorn-cynative-aws-privilege-escalation.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mvanhorn/cynative/HEAD/agents/aws-privilege-escalation.md -o ~/.claude/agents/mvanhorn-cynative-aws-privilege-escalation.md Restart Claude Code, or start a new session, for it to be picked up.
What AWS Privilege Escalation does
description: Map the paths from each AWS IAM principal to administrative control, naming the calls that walk each one.
Research which IAM users, roles and groups in this account can reach administrative control, and which API calls walk each path.
Take the principals with their inline and attached policy from the account authorization details filtered to users, roles, groups and customer-managed policies, then read each attached AWS-managed policy once rather than the whole catalogue,
Alternatives in DevOps & Infrastructure
- Secrets Management — Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other 31.9k ★
- Cloud Architect — Cloud architect for AWS/Azure/GCP infrastructure, IaC, FinOps, and multi-cloud strategies 2.8k ★
- AWS Agent Skills — Supercharge Claude Code with AWS cloud engineering skills across 18 core AWS services 1k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Cloud Attacker
Cloud penetration testing specialist for AWS, Azure, and GCP. Handles IAM enumeration, privilege escalation, S
AWS Architect
AWS solutions architect: Well-Architected reviews, multi-account landing zones with AWS Organizations and Cont
AWS Behavior Anomalies
Find the CloudTrail escalation and enumeration sequences that depart from what the principal running them norm
Cost Control Reviewer
Reviews architecture and infrastructure for cost efficiency across AWS, Azure, and GCP. Use when provisioning
AWS Detection Coverage
Find the AWS regions and alarm paths where activity would generate no signal that reaches anyone.
AWS Specialist
AWS infrastructure specialist. Lambda, SQS, S3, RDS, IAM, and serverless patterns. Use when designing AWS arch
Related Skills
AWS Security Skills
Claude Code skills for AWS security: a plugin with five skills for a read-only account audit, SCP guardrail bu
Compliance Evidence Skills
Claude Code skills for compliance evidence: a plugin with five skills that pack GitHub, AWS and Microsoft 365
Auth Audit
Full auth & session audit: login flow, session/cookie security, JWT handling, middleware safety, privilege esc